Earlier quoted context omitted.
So "big companies only, absolutely no anonymous sign-ups" should be the only ones able to put stuff on the internet without fearing that a random teenager can take your site offline for days just because they're bored?
No. Nobody said that. Cloudflare should simply enforce basic rules, like "don't run a cybercrime storefront", rather than letting criminal operations like this proliferate.
Can someone please explain whether Cloudflare blackmailed Canonical?
141–150 of 182 posts
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#142"Anonymous person on the internet claiming " is proof of nothing.
It's just as likely someone claimed they used Beamed to try to get a competing service taken down or direct attention elsewhere.
Don't get my wrong, Beamed looks like a scummy booter service with no legal purpose.
However, claiming companies should deplatform sites based on speculation is, imo, a very dangerous precedent.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#143Earlier quoted context omitted.
Yeah, probably not - because they don't explicitly have to, as outlined in the post. The very architecture of CF's services essentially enables "blackmail as a service" in the sense that, CF protects the attacker and essentially creates a coercive environment in which the victim "has" to pay CF to protect them from... the very attacker that CF protects.
> and essentially creates a coercive environment This is the part that's wrong. CF is not creating the fact that sites are vulnerable to DDoS, and these attacks would happen even if the sites were kicked off. If some guys are going around slashing tires, would we demand that tire repair shops not sell to them? Would we say it's blackmail because the tire shop sells to anyone, and selling tires to them "creates a coer…
I think it's fair to assume that would cause some reactions.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#144Earlier quoted context omitted.
> and essentially creates a coercive environment This is the part that's wrong. CF is not creating the fact that sites are vulnerable to DDoS, and these attacks would happen even if the sites were kicked off. If some guys are going around slashing tires, would we demand that tire repair shops not sell to them? Would we say it's blackmail because the tire shop sells to anyone, and selling tires to them "creates a coer…
A tire repair shop that also hosted a the National Tire Slashing Club for free in the back? I think it's fair to assume that would cause some reactions.
If the back of the store was a convention center that allowed basically any small club to use it for free, and of their many thousands of hosted clubs one or two were focused around tire slashing, that wouldn't cause the same reactions.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#145Earlier quoted context omitted.
How? Their sign-up flow would have to change dramatically. It might even become a process that is internally "expensive". There is likely one or more managers in charge of this decision and they don't want it. Additionally the current universe rewards the current situation (for them)
This is called KYC and is a standard part of operating a financial service. Seems to me like it should be part of internet infrastructure services as well. And, I thought, in some cases already is?
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#146Earlier quoted context omitted.
Most companies have TOS that include not damaging or attacking the company itself. The advertised service attacks Cloudflare explicitly. It seems very straightforward that this would violate any reasonable TOS. edit: and here it is straight from their TOS https://www.cloudflare.com/en-ca/website-terms/ "7. PROHIBITED USES As a condition of your use of the Websites and Online Services, you will not use the Websites or…
cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…
thus being used for illegal and harmful activities right?
> Cloudflare retains the right (but not the obligation) to block content from its Distributed Web Gateway that Cloudflare determines (in its sole discretion) to be illegal, harmful
Not that I have any hope for TOS violation claims. I've learned early on in life that people generally don't care in life if you violate rules they invented if they're not impacted themselves. They do care if they violate someone else's rules and there is a chance of repercussions. There are exceptions, quite a few hosting companies in fact, but Cloudflare so far hasn't acted like a party that has the good of the web in its interest (even when strictly speaking of whom they offer services to despite them doing harm). Just wanted to point out that the cited clause, assuming it is correct as stated above, could be applied at Cloudflare's discretion if they so wished
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#147Earlier quoted context omitted.
cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…
> the webpage being hosted by cloudflare, which is just a marketing page and a login portal thus being used for illegal and harmful activities right? > Cloudflare retains the right (but not the obligation) to block content from its Distributed Web Gateway that Cloudflare determines (in its sole discretion) to be illegal, harmful Not that I have any hope for TOS violation claims. I've learned early on in life that peo…
neither the login portal page nor the marketing page are illegal.
>Cloudflare so far hasn't acted like a party that has the good of the web in its interest
for a lot of reasons, i generally agree with this statement. however, for this specific reason (maintaining a content-neutral approach, instead of playing content-police), i could not disagree more. cloudflare making hosting decisions based on the legal content of your site would be a huge disservice to the internet.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#148Earlier quoted context omitted.
In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…
It's been a well known story around Cloudflare from the beginning that they protect booters and other cybercrime actors just like any other (paying or non-paying) customer. If you report the DDoS-for-hire actors that offer their services on forums where such things are offered openly, they reply with a template that freely interpreted say something along the lines that they can do nothing and who is a crimininal is .…
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#149"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.
In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#150With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.
This is a service, not a device sale. Continuing to provide a service to an organization that is using it to support criminal activity is very different and terminating clients for illegal activity is not controversial.
It's the customers of Beamed doing the illegal activity and not Beamed themselves.